CVE Feed

    Dashboard / CVE

    4.4
    Medium

    CVE-2021-0677

    Last Modified: 21 Nov 2024

    In ccu driver, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05827154; Issue ID: ALPS05827154.

    Published: 17 Dec 2021
    7.5
    High

    CVE-2021-32499

    Last Modified: 21 Nov 2024

    SICK SOPAS ET before version 4.8.0 allows attackers to manipulate the command line arguments to pass in any value to the Emulator executable.

    Published: 17 Dec 2021
    8.6
    High

    CVE-2021-32498

    Last Modified: 21 Nov 2024

    SICK SOPAS ET before version 4.8.0 allows attackers to manipulate the pathname of the emulator and use path traversal to run an arbitrary executable located on the host system. When the user starts the emulator from SOPAS ET the corresponding executable will be started instead of the emulator

    Published: 17 Dec 2021
    8.6
    High

    CVE-2021-32497

    Last Modified: 21 Nov 2024

    SICK SOPAS ET before version 4.8.0 allows attackers to wrap any executable file into an SDD and provide this to a SOPAS ET user. When a user starts the emulator the executable is run without further checks.

    Published: 17 Dec 2021
    4.4
    Medium

    CVE-2021-44035

    Last Modified: 30 May 2025

    Wolters Kluwer TeamMate AM 12.4 Update 1 mishandles attachment uploads, such that an authenticated user may download and execute malicious files.

    Published: 17 Dec 2021
    7.5
    High

    CVE-2021-41451

    Last Modified: 21 Nov 2024

    A misconfiguration in HTTP/1.0 and HTTP/1.1 of the web interface in TP-Link AX10v1 before V1_211117 allows a remote unauthenticated attacker to send a specially crafted HTTP request and receive a misconfigured HTTP/0.9 response, potentially leading into a cache poisoning attack.

    Published: 17 Dec 2021
    5.4
    Medium

    CVE-2021-42584

    Last Modified: 21 Nov 2024

    A Stored Cross Site Scripting (XSS) issue exists in Convos-Chat before 6.32.

    Published: 17 Dec 2021
    6.1
    Medium

    CVE-2021-43678

    Last Modified: 21 Nov 2024

    Wechat-php-sdk v1.10.2 is affected by a Cross Site Scripting (XSS) vulnerability in Wechat.php.

    Published: 17 Dec 2021
    5.4
    Medium

    CVE-2021-4132

    Last Modified: 21 Nov 2024

    livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    Published: 17 Dec 2021
    8.1
    High

    CVE-2021-36780

    Last Modified: 21 Nov 2024

    A Missing Authentication for Critical Function vulnerability in longhorn of SUSE Longhorn allows attackers to connect to a longhorn-engine replica instance granting it the ability to read and write data to and from a replica that they should not have access to. This issue affects: SUSE Longhorn longhorn versions prior to 1.1.3; longhorn versions prior to 1.2.3v.

    Published: 17 Dec 2021
    9.6
    Critical

    CVE-2021-36779

    Last Modified: 21 Nov 2024

    A Missing Authentication for Critical Function vulnerability in SUSE Longhorn allows any workload in the cluster to execute any binary present in the image on the host without authentication. This issue affects: SUSE Longhorn longhorn versions prior to 1.1.3; longhorn versions prior to 1.2.3.

    Published: 17 Dec 2021
    6.5
    Medium

    CVE-2021-44145

    Last Modified: 21 Nov 2024

    In the TransformXML processor of Apache NiFi before 1.15.1 an authenticated user could configure an XSLT file which, if it included malicious external entity calls, may reveal sensitive information.

    Published: 17 Dec 2021
    6.5
    Medium

    CVE-2021-41843

    Last Modified: 21 Nov 2024

    An authenticated SQL injection issue in the calendar search function of OpenEMR 6.0.0 before patch 3 allows an attacker to read data from all tables of the database via the parameter provider_id, as demonstrated by the /interface/main/calendar/index.php?module=PostCalendar&func=search URI.

    Published: 17 Dec 2021
    5.3
    Medium

    CVE-2021-45471

    Last Modified: 21 Nov 2024

    In MediaWiki through 1.37, blocked IP addresses are allowed to edit EntitySchema items.

    Published: 17 Dec 2021
    6.1
    Medium

    CVE-2021-45474

    Last Modified: 21 Nov 2024

    In MediaWiki through 1.37, the Special:ImportFile URI (aka FileImporter) allows XSS, as demonstrated by the clientUrl parameter.

    Published: 17 Dec 2021
    6.5
    Medium

    CVE-2021-45482

    Last Modified: 21 Nov 2024

    In WebKitGTK before 2.32.4, there is a use-after-free in WebCore::ContainerNode::firstChild, a different vulnerability than CVE-2021-30889.

    Published: 17 Dec 2021
    6.1
    Medium

    CVE-2021-45472

    Last Modified: 21 Nov 2024

    In MediaWiki through 1.37, XSS can occur in Wikibase because an external identifier property can have a URL format that includes a $1 formatter substitution marker, and the javascript: URL scheme (among others) can be used.

    Published: 17 Dec 2021
    6.5
    Medium

    CVE-2021-45481

    Last Modified: 21 Nov 2024

    In WebKitGTK before 2.32.4, there is incorrect memory allocation in WebCore::ImageBufferCairoImageSurfaceBackend::create, leading to a segmentation violation and application crash, a different vulnerability than CVE-2021-30889.

    Published: 17 Dec 2021
    6.5
    Medium

    CVE-2021-45483

    Last Modified: 21 Nov 2024

    In WebKitGTK before 2.32.4, there is a use-after-free in WebCore::Frame::page, a different vulnerability than CVE-2021-30889.

    Published: 17 Dec 2021
    5.5
    Medium

    CVE-2021-3179

    Last Modified: 21 Nov 2024

    GGLocker iOS application, contains an insecure data storage of the password hash value which results in an authentication bypass.

    Published: 16 Dec 2021
    6.5
    Medium

    CVE-2021-26800

    Last Modified: 21 Nov 2024

    Cross Site Request Forgery (CSRF) vulnerability in Change-password.php in phpgurukul user management system in php using stored procedure V1.0, allows attackers to change the password to an arbitrary account.

    Published: 16 Dec 2021
    8.4
    High

    CVE-2021-43837

    Last Modified: 21 Nov 2024

    vault-cli is a configurable command-line interface tool (and python library) to interact with Hashicorp Vault. In versions before 3.0.0 vault-cli features the ability for rendering templated values. When a secret starts with the prefix `!template!`, vault-cli interprets the rest of the contents of the secret as a Jinja2 template. Jinja2 is a powerful templating engine and is not designed to safely render arbitrary templates. An attacker controlling a jinja2 template rendered on a machine can trigger arbitrary code, making this a Remote Code Execution (RCE) risk. If the content of the vault can be completely trusted, then this is not a problem. Otherwise, if your threat model includes cases where an attacker can manipulate a secret value read from the vault using vault-cli, then this vulnerability may impact you. In 3.0.0, the code related to interpreting vault templated secrets has been removed entirely. Users are advised to upgrade as soon as possible. For users unable to upgrade a workaround does exist. Using the environment variable `VAULT_CLI_RENDER=false` or the flag `--no-render` (placed between `vault-cli` and the subcommand, e.g. `vault-cli --no-render get-all`) or adding `render: false` to the vault-cli configuration yaml file disables rendering and removes the vulnerability. Using the python library, you can use: `vault_cli.get_client(render=False)` when creating your client to get a client that will not render templated secrets and thus operates securely.

    Published: 16 Dec 2021
    5.4
    Medium

    CVE-2021-44317

    Last Modified: 21 Nov 2024

    In Bus Pass Management System v1.0, parameters 'pagedes' and `About Us` are affected with a Stored Cross-site scripting vulnerability.

    Published: 16 Dec 2021
    7.5
    High

    CVE-2021-44315

    Last Modified: 21 Nov 2024

    In Bus Pass Management System v1.0, Directory Listing/Browsing is enabled on the web server which allows an attacker to view the sensitive files of the application, for example: Any file which contains sensitive information of the user or server.

    Published: 16 Dec 2021
    6.4
    Medium

    CVE-2021-43812

    Last Modified: 21 Nov 2024

    The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions before 1.6.2 do not filter out certain returnTo parameter values from the login url, which expose the application to an open redirect vulnerability. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.

    Published: 16 Dec 2021
    7.5
    High

    CVE-2021-38244

    Last Modified: 21 Nov 2024

    A regular expression denial of service (ReDoS) vulnerability exits in cbioportal 3.6.21 and older via a POST request to /ProteinArraySignificanceTest.json.

    Published: 16 Dec 2021
    8.2
    High

    CVE-2021-41028

    Last Modified: 21 Nov 2024

    A combination of a use of hard-coded cryptographic key vulnerability [CWE-321] in FortiClientEMS 7.0.1 and below, 6.4.6 and below and an improper certificate validation vulnerability [CWE-297] in FortiClientWindows, FortiClientLinux and FortiClientMac 7.0.1 and below, 6.4.6 and below may allow an unauthenticated and network adjacent attacker to perform a man-in-the-middle attack between the EMS and the FCT via the telemetry protocol.

    Published: 16 Dec 2021
    8.1
    High

    CVE-2021-41261

    Last Modified: 21 Nov 2024

    Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions prior to 0.9.6 are subject to stored cross site scripting attacks via the preferences footer. The preference footer can only be altered by a site admin. This issue has been resolved in the 0.9.6 release and all users are advised to upgrade. There are no known workarounds.

    Published: 16 Dec 2021
    8.8
    High

    CVE-2021-41262

    Last Modified: 21 Nov 2024

    Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions prior to 0.9.6 are subject to SQL injection attacks by users with "member" privilege. Users are advised to upgrade to version 0.9.6 as soon as possible. There are no known workarounds.

    Published: 16 Dec 2021
    8.2
    High

    CVE-2021-41260

    Last Modified: 21 Nov 2024

    Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions prior to 0.9.6 do not check for Cross Site Request Forgery attacks. All users are advised to upgrade to 0.9.6 as soon as possible. There are no known workarounds for this issue.

    Published: 16 Dec 2021
    7.5
    High

    CVE-2021-37262

    Last Modified: 21 Nov 2024

    JFinal_cms 5.1.0 is vulnerable to regex injection that may lead to Denial of Service.

    Published: 16 Dec 2021
    4.8
    Medium

    CVE-2021-41962

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the Owner fullname parameter in a Send Service Request in vehicle_service.

    Published: 16 Dec 2021
    8.8
    High

    CVE-2021-4133

    Last Modified: 21 Nov 2024

    A flaw was found in Keycloak in versions from 12.0.0 and before 15.1.1 which allows an attacker with any existing user account to create new default user accounts via the administrative REST API even when new user registration is disabled.

    Published: 16 Dec 2021
    8.8
    High

    CVE-2021-42912

    Last Modified: 4 Jul 2026

    FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection vulnerability. This vulnerability allows the attacker, once logged in, to send commands to the operating system as the root user via the ping diagnostic tool, bypassing the IP address field, and concatenating OS commands with a semicolon.

    Published: 16 Dec 2021
    7.1
    High

    CVE-2021-3960

    Last Modified: 21 Nov 2024

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances. This issue affects Bitdefender GravityZone versions prior to 3.3.8.272

    Published: 16 Dec 2021
    6.8
    Medium

    CVE-2021-3959

    Last Modified: 21 Nov 2024

    A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService component of Bitdefender Endpoint Security Tools allows an attacker to proxy requests to the relay server. This issue affects: Bitdefender Bitdefender GravityZone versions prior to 3.3.8.272

    Published: 16 Dec 2021
    6.1
    Medium

    CVE-2021-4124

    Last Modified: 21 Nov 2024

    janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    Published: 16 Dec 2021
    4.6
    Medium

    CVE-2021-40835

    Last Modified: 21 Nov 2024

    An URL Address bar spoofing vulnerability was discovered in Safe Browser for iOS. When user clicks on a specially crafted a malicious URL, if user does not carefully pay attention to url, user may be tricked to think content may be coming from a valid domain, while it comes from another. This is performed by using a very long username part of the url so that user cannot see the domain name. A remote attacker can leverage this to perform url address bar spoofing attack. The fix is, browser no longer shows the user name part in address bar.

    Published: 16 Dec 2021
    6.5
    Medium

    CVE-2021-4123

    Last Modified: 21 Nov 2024

    livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)

    Published: 16 Dec 2021
    6.1
    Medium

    CVE-2021-4121

    Last Modified: 21 Nov 2024

    yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    Published: 16 Dec 2021
    8.8
    High

    CVE-2021-45102

    Last Modified: 21 Nov 2024

    An issue was discovered in HTCondor 9.0.x before 9.0.4 and 9.1.x before 9.1.2. When authenticating to an HTCondor daemon using a SciToken, a user may be granted authorizations beyond what the token should allow.

    Published: 16 Dec 2021
    8.1
    High

    CVE-2021-45101

    Last Modified: 21 Nov 2024

    An issue was discovered in HTCondor before 8.8.15, 9.0.x before 9.0.4, and 9.1.x before 9.1.2. Using standard command-line tools, a user with only READ access to an HTCondor SchedD or Collector daemon can discover secrets that could allow them to control other users' jobs and/or read their data.

    Published: 16 Dec 2021
    8.8
    High

    CVE-2021-45099

    Last Modified: 21 Nov 2024

    The addon.stdin service in addon-ssh (aka Home Assistant Community Add-on: SSH & Web Terminal) before 10.0.0 has an attack surface that requires social engineering. NOTE: the vendor does not agree that this is a vulnerability; however, addon.stdin was removed as a defense-in-depth measure against complex social engineering situations

    Published: 16 Dec 2021
    7.5
    High

    CVE-2021-45098

    Last Modified: 3 Nov 2025

    An issue was discovered in Suricata before 6.0.4. It is possible to bypass/evade any HTTP-based signature by faking an RST TCP packet with random TCP options of the md5header from the client side. After the three-way handshake, it's possible to inject an RST ACK with a random TCP md5header option. Then, the client can send an HTTP GET request with a forbidden URL. The server will ignore the RST ACK and send the response HTTP packet for the client's request. These packets will not trigger a Suricata reject action.

    Published: 16 Dec 2021
    9.8
    Critical

    CVE-2021-45092

    Last Modified: 21 Nov 2024

    Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection via the vpath parameter.

    Published: 16 Dec 2021
    7.1
    High

    CVE-2021-44023

    Last Modified: 21 Nov 2024

    A link following denial-of-service (DoS) vulnerability in the Trend Micro Security (Consumer) 2021 familiy of products could allow an attacker to abuse the PC Health Checkup feature of the product to create symlinks that would allow modification of files which could lead to a denial-of-service.

    Published: 16 Dec 2021
    6.1
    Medium

    CVE-2021-45086

    Last Modified: 21 Nov 2024

    XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 because a server's suggested_filename is used as the pdf_name value in PDF.js.

    Published: 16 Dec 2021
    6.1
    Medium

    CVE-2021-45087

    Last Modified: 21 Nov 2024

    XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 when View Source mode or Reader mode is used, as demonstrated by a a page title.

    Published: 16 Dec 2021
    6.1
    Medium

    CVE-2021-45088

    Last Modified: 21 Nov 2024

    XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an error page.

    Published: 16 Dec 2021
    6.1
    Medium

    CVE-2021-45085

    Last Modified: 21 Nov 2024

    XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an about: page, as demonstrated by ephy-about:overview when a user visits an XSS payload page often enough to place that page on the Most Visited list.

    Published: 16 Dec 2021